Cybercriminals are slashing the prices of RDP passwords. The move highlights how leaked usernames and passwords are becoming increasingly available to hackers as a means of gaining access to corporate networks – and highlights how weak passwords continue to be a scourge of corporate security.
Remote Desktop Protocol (RDP) allows employees to securely connect to their organization's servers remotely — a practice that has grown in 2020 as employees increasingly work from home. RDP is also regularly used by administrator, allowing IT and security teams to perform updates and provide assistance to users.

However, while extremely useful, an improperly secured RDP account or server can provide cybercriminals with easy access to a corporate network with either stolen or easily guessed passwords.
Armor researchers analyzed 15 different online marketplaces on the dark web and hacking forums and found that the average price for RDP credentials has dropped between $16 and $25, compared to an average of over $20 during 2019. Some dark web advertise these credentials as “unhacked,” claiming they have not been used in the past.
In many cases, the reason why stolen RDP login credentials became available in the first place is because they are poorly secured with weak passwords, as well as simple usernames like "administrator.".
Attackers who purchase the credentials could use the login details for anything from performing network reconnaissance to using them as a gateway to steal additional usernames and passwords or confidential information. They could also use the RDP credentials as the first stage of a larger malware or ransomware.
And the way the cost of RDP credentials is decreasing shows that the problem is getting worse, implying that prices are falling as online stores on the dark web become saturated with more and more RDPs.
It is possible that more login credentials have become available due to the increase in remote work during this year.
